Server IP : 162.214.80.37 / Your IP : 216.73.216.83 Web Server : Apache System : Linux sh013.webhostingservices.com 4.19.286-203.ELK.el7.x86_64 #1 SMP Wed Jun 14 04:33:55 CDT 2023 x86_64 User : imyrqtmy ( 2189) PHP Version : 8.2.18 Disable Function : NONE MySQL : OFF | cURL : ON | WGET : ON | Perl : ON | Python : ON Directory (0755) : /home2/imyrqtmy/public_html/destinationplanner/admin/ |
[ Home ] | [ C0mmand ] | [ Upload File ] |
---|
<?php session_start(); include("includes/config.php"); if (isset($_POST['add_destination'])) { $destination_name = mysqli_real_escape_string($conn, $_POST['destination_name']); // $description = mysqli_real_escape_string($conn, $_POST['description'] ?? ''); $photo = $_FILES['photo']['name'] ?? null; // Check if file exists $allowed_image_extensions = array('gif', 'png', 'jpg', 'jpeg', 'webp', 'WEBP'); if ($photo) { $photo_file_extension = pathinfo($photo, PATHINFO_EXTENSION); if (!in_array($photo_file_extension, $allowed_image_extensions)) { $_SESSION['status'] = "The image file is not allowed. Please upload an image."; header('Location: destination.php'); exit; } move_uploaded_file($_FILES["photo"]["tmp_name"], "destination/" . $photo); } // Prepare SQL query if ($photo) { $query = "INSERT INTO destinations (destination_name, photo) VALUES ('$destination_name', '$photo')"; } else { $query = "INSERT INTO destinations (destination_name) VALUES ('$cat_name')"; } $query_run = mysqli_query($conn, $query); if ($query_run) { $_SESSION['status'] = "Uploaded Successfully"; echo "<script>window.location.href='view-destination.php';</script>"; exit; } else { $_SESSION['status'] = "Not Uploaded"; echo "<script>window.location.href='view-destination.php';</script>"; exit; } } // session_start(); // include("includes/config.php"); // if (isset($_POST['add_cat'])) { // $cat_name = $_POST['cat_name']; // $photo = $_FILES['photo']['name'] ?? null; // $allowed_image_extensions = array('gif', 'png', 'jpg', 'jpeg', 'webp', 'WEBP'); // if ($photo) { // $photo_file_extension = pathinfo($photo, PATHINFO_EXTENSION); // if (!in_array($photo_file_extension, $allowed_image_extensions)) { // $_SESSION['status'] = "The image file is not allowed. Please upload an image."; // header('Location: category.php'); // exit; // } // move_uploaded_file($_FILES["photo"]["tmp_name"], "category/" . $photo); // } // if ($photo) { // $query = "INSERT INTO categories (cat_name, photo) VALUES ('$cat_name', '$description', '$photo')"; // } else { // $query = "INSERT INTO categories (cat_name) VALUES ('$cat_name', '$description')"; // } // $query_run = mysqli_query($conn, $query); // if ($query_run) { // $_SESSION['status'] = "Uploaded Successfully"; // echo "<script>window.location.href='view-category.php';</script>"; // exit; // } else { // $_SESSION['status'] = "Not Uploaded"; // echo "<script>window.location.href='view-category.php';</script>"; // exit; // } // } // update if(isset($_POST['update_destination'])){ $id = $_POST['id']; $destination_name = $_POST['destination_name']; $old_photo = $_POST['image_old']; $update_photo_filename = $_FILES["photo"]["name"] ? $_FILES["photo"]["name"] : $old_photo; $query = "UPDATE destinations SET destination_name='$destination_name', photo='$update_photo_filename' WHERE id ='$id' "; $query_run = mysqli_query($conn, $query); if($query_run){ if($_FILES["photo"]["name"] !='' && $_FILES["photo"]["name"] != $old_photo){ move_uploaded_file($_FILES["photo"]["tmp_name"], "destination/".$_FILES["photo"]["name"]); unlink("destination/". $old_photo); } $_SESSION['status'] = "Updated Successfully"; echo "<script>window.location.href='view-destination.php';</script>"; // header('Location: view-category.php'); } else { $_SESSION['status'] = "Not Updated "; echo "<script>window.location.href='view-destination.php';</script>"; // header('Location: view-category.php'); } } // delete if(isset($_POST['delete_destination'])){ $id = $_POST['delete_id']; $photo = $_POST['del_destination']; $query = "DELETE FROM destinations WHERE id = '$id'"; $query_run = mysqli_query($conn, $query); if($query_run){ $_SESSION['status'] = "Deleted Successfully"; echo "<script>window.location.href='view-destination.php';</script>"; // header('Location: view-category.php'); } else { $_SESSION['status'] = "Not Deleted Successfully"; echo "<script>window.location.href='view-destination.php';</script>"; // header('Location: view-category.php'); } }